Database/Firmware, BMC & network fabric
Supermicro BMC web interface (stack buffer overflow, X13SEDW-F): Second authenticated stack overflow in the BMC web
Impact
Second authenticated stack overflow in the BMC web function, giving full BMC compromise.
Who can reach it
Authenticated BMC web access with high privilege.
What to do
Flash the fixed Supermicro BMC firmware for the affected board SKU. BMC flash does not require a host reboot, but it does drop out-of-band management for several minutes per node - script it and stagger it so you never lose OOB across a whole rack at once. Check your exact MBD- part number against the advisory; Supermicro scopes these narrowly. Ships in the same November 2025 firmware batch as the other CoreWeave-reported findings.
References
Related entries
- Perle IOLAN STS/SCS terminal server (firmware before 6.0): A logged-in user of the restricted admin shell (TelnetCVE-2026-23759 · Perle IOLAN STS/SCS terminal server (firmware before 6.0)High
- Supermicro BMC SMTP service configuration handler on AS-2115HS-TNR and related boards: Crafted characters injectedCVE-2026-3820 · Supermicro BMC SMTP service configuration handler on AS-2115HS-TNR and related boardsHigh
- Dell OMSA: high-privileged remote user escalates beyond their assigned OMSA roleCVE-2026-81445 · Dell OpenManage Server Administrator (privilege management, admin-level)High
- Dell OMSA: remote heap overflow gives code execution to a high-privileged accountCVE-2026-81477 · Dell OpenManage Server Administrator (remote heap-based buffer overflow)High
- Dell OMSA: remote stack overflow gives code execution to a high-privileged accountCVE-2026-81480 · Dell OpenManage Server Administrator (stack-based buffer overflow)High
- Intel CSME / Converged Security and Management Engine (mask ROM): A flaw in the CSME boot ROM window before memoryCVE-2019-0090 · Intel CSME / Converged Security and Management Engine (mask ROM)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.